logo

High-Severity ingress-nginx Flaw Exposes Kubernetes Secrets

ID: a1487733-8da6-56b4-8d7e-c7aaec0d183f

STIX ID: report--a1487733-8da6-56b4-8d7e-c7aaec0d183f

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2026-4342, CVSS 8.8) in ingress-nginx allows attackers to craft Ingress annotations that inject arbitrary configuration into Nginx, potentially enabling remote code execution and exposure of Kubernetes Secrets; affected versions are earlier than v1.13.9, v1.14.5, and v1.15.1, and administrators are advised to check for ingress-nginx pods, inspect rules.http.paths.path for suspicious data, and promptly upgrade to patched releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.